Improper Certificate Validation in Calcite - CVE-2020-13955
Published: October 9, 2020 / Updated: October 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splunk so information leakage may happen when using the respective Calcite adapters.
Affected software
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
How to mitigate CVE-2020-13955
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Qradar SIEM - update to 7.5.0 Update Pack 6